docs(security): record first-release security review - #1
Closed
CompleteDotTech wants to merge 2 commits into
Closed
Conversation
CompleteDotTech
force-pushed
the
security/first-release-review-40
branch
from
August 30, 2026 08:56
82f69d7 to
100b726
Compare
CompleteDotTech
marked this pull request as ready for review
August 30, 2026 09:18
This was referenced Aug 30, 2026
Owner
Author
|
Recreated upstream as OpenCoven#76: OpenCoven#76. Closing this duplicate fork PR; review continues upstream. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Assignee: @CompleteDotTech
Advances OpenCoven#40 (ship/block disposition for OpenCoven#41)
Upstream PR (one click for a maintainer): https://github.com/OpenCoven/sdk/compare/main...CompleteDotTech:sdk:security/first-release-review-40?expand=1
Summary
Records the issue OpenCoven#40 first-release security review as a dated doc:
docs/security/2026-08-29-first-release-security-review.md.4736bf2e0d5b16272d79ecf7784c75f376b39b94(origin/main HEAD at review time), fixed 0.1.0 group (@opencoven/sdk-core,@opencoven/cave-client,@opencoven/coven-client,@opencoven/sdk, allprivate: true), Node>=24.18.0 <25, native-conformance matrixdarwin-arm64/linux-x64/win32-x64.publishingEnabledisfalse; token-based npm auth is forbidden by construction (scripts/publish-release-artifacts.mjs:58-62); publication is OIDC trusted publishing only.git log -p --allhistory scan found no real credentials (only synthetic test constants).conformanceEvidence.aggregateRecordgate enforces this), 2 x accepted-with-owner (F-2: no security-response SLA promised, revisit 2026-09-30; F-3: authorization env var is workflow-internal, superseded by PR feat: enforce cross-repository conformance evidence OpenCoven/sdk#74 environment-approval receipts), 0 x fixed-and-verified.Advances OpenCoven#40 (ship/block disposition gating OpenCoven#41).
Assignee: @CompleteDotTech
Validation performed
On the reviewed commit, in a clean worktree under Node 24.18.1 / pnpm 10.34.0:
corepack pnpm@10.34.0 verify(canonical gate): exit 0 — typecheck, 58 test files / 1213 tests passed,verify:contracts,verify:package,verify:release, coverage 90.11% statements, operation-property stress, lint--max-warnings=0.corepack pnpm@10.34.0 audit: "No known vulnerabilities found".corepack pnpm@10.34.0 pack:public: exactly four tarballs (private CLI excluded), dist/fixtures/metadata only, no install lifecycle scripts; packed tarballs installed offline into a throwaway dir and@opencoven/sdk/@opencoven/cave-clientimported successfully.node ./scripts/verify-release-readiness.mjs --mode publish …: exit 1 — "Release publishing is disabled by release.config.json" (also via the publish script in all env-var permutations). No publish, tag, unlock, or workflow dispatch was performed.